LWN.net Logo

Foreman: multiple vulnerabilities

Package(s):Foreman CVE #(s):CVE-2013-2113 CVE-2013-2121
Created:June 28, 2013 Updated:July 3, 2013
Description:

From the Red Hat advisory:

A flaw was found in the create method of the Foreman Bookmarks controller. A user with privileges to create a bookmark could use this flaw to execute arbitrary code with the privileges of the user running Foreman, giving them control of the system running Foreman (such as installing new packages) and all systems managed by Foreman. (CVE-2013-2121)

A flaw was found in the way the Foreman UsersController controller handled user creation. A non-admin user with privileges to create non-admin accounts could use this flaw to create admin accounts, giving them control of the system running Foreman (such as installing new packages) and all systems managed by Foreman. (CVE-2013-2113)

Alerts:
Red Hat RHSA-2013:0995-01 2013-06-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds